Networking Forums  

Go Back   Networking Forums > Networking Newsgroups > Windows Server Networking

IPSec policy on servers connected to 2 networks

Reply
 
Thread Tools Display Modes
  #1  
Old 11-18-2007, 06:08 PM
Default IPSec policy on servers connected to 2 networks



Hi. I am currently investigating how to setup an IPSec policy on a small
network (single domain) of ~20 windows 2003 and 2000 servers and ~10 windows
xp and 2000 workstations. Of the 20 servers 5 of them are directly
connected to other networks via a second nic, the IP address ranges of these
second network connections also vary.

If possible can anyone advise how I can deploy a policy to enable IPSec on
the internal domain traffic while still allowing these 5 servers to continue
communicating to their second network in the clear ? I'm comfortable with
setting up IPSec, it's how to handle the two network issue I'm stuck on.

Thanks,
Stuart.



Stuart
Reply With Quote
  #2  
Old 11-20-2007, 04:20 AM
Steve Riley [MSFT]
Guest
 
Posts: n/a
Default Re: IPSec policy on servers connected to 2 networks

Except for when you indicate the interface type (all, LAN, or remote), the
IPsec engine doesn't care about interfaces -- it concerns itself only with
IP addresses and any rules that match those addresses.

What kind of policies do you want on the internal domain?


--
Steve Riley
(E-Mail Removed)
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


"Stuart" <newsgroups> wrote in message
news:(E-Mail Removed)...
> Hi. I am currently investigating how to setup an IPSec policy on a small
> network (single domain) of ~20 windows 2003 and 2000 servers and ~10
> windows xp and 2000 workstations. Of the 20 servers 5 of them are
> directly connected to other networks via a second nic, the IP address
> ranges of these second network connections also vary.
>
> If possible can anyone advise how I can deploy a policy to enable IPSec on
> the internal domain traffic while still allowing these 5 servers to
> continue communicating to their second network in the clear ? I'm
> comfortable with setting up IPSec, it's how to handle the two network
> issue I'm stuck on.
>
> Thanks,
> Stuart.


Reply With Quote
  #3  
Old 11-20-2007, 03:59 PM
Roger Abell [MVP]
Guest
 
Posts: n/a
Default Re: IPSec policy on servers connected to 2 networks

Instead of defining your rules as to/from My Address define
them using to/from IP of concern for the traffic type.

"Stuart" <newsgroups> wrote in message
news:(E-Mail Removed)...
> Hi. I am currently investigating how to setup an IPSec policy on a small
> network (single domain) of ~20 windows 2003 and 2000 servers and ~10
> windows xp and 2000 workstations. Of the 20 servers 5 of them are
> directly connected to other networks via a second nic, the IP address
> ranges of these second network connections also vary.
>
> If possible can anyone advise how I can deploy a policy to enable IPSec on
> the internal domain traffic while still allowing these 5 servers to
> continue communicating to their second network in the clear ? I'm
> comfortable with setting up IPSec, it's how to handle the two network
> issue I'm stuck on.
>
> Thanks,
> Stuart.



Reply With Quote
Reply

Tags
connected, ipsec, networks, policy, servers

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 03:30 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.